All Newsletters

Valid Points · September 2025

YARA Rules, Joint Research with SentinelLabs, and Pivots Revisited

We're excited to announce threat hunting using YARA rules, share our latest joint research with SentinelLabs, and more in our monthly newsletter.

Welcome back to Validin's monthly newsletter and thank you for inviting us into your inbox. This past month we collaborated with SentinelOne to publish new research that uncovered how North Korean operators use intelligence platforms, which was covered by international news agency Reuters, interviewing victims of the campaign. Additionally, we are excited to announce YARA rule hunting capabilities to Enterprise customers. As always, we appreciate any feedback! - The Validin Team

September 2025 Newsletter Validin (1)

PRODUCT UPDATES

Introducing YARA Rules

This month, we’ve made a significant improvement to how our users are able to query our data by allowing them to write custom YARA rules to retroactively scan our virtual host responses. This allows you to more accurately fingerprint, track, and discover novel threat indicators. We’re making this capability available to all of our enterprise customers. In this blog, we present a guide on how to compose and run a YARA rule in the Validin enterprise platform and showcase a use case we’ve come across during our testing. 👉 See what’s new

north korean threat actor research

FEATURED RESEARCH

Contagious Interview: North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms

We partnered with SentinelOne's threat research team to uncover how North Korea-aligned threat actors actively monitored cyber threat intelligence to detect infrastructure exposure and scout for new assets. Their tactics included the ClickFix technique, which lures job seekers into executing malicious commands, leading to at least 230 confirmed victims in early 2025. 👉 Read the full report

Additionally, Reuters covered the human dimension of this campaign, exploring victim engagement methods and their personal impact. 👉 Read the article

IN CASE YOU MISSED IT

LABScon 2025 Highlights

CAN YOU SPOT US?

Validin Takes LABScon 2025

The Validin team had a blast attending and sponsoring LABScon, SentinelOne's annual threat research conference. 👉 Watch the highlight reel

BY THE NUMBERS

September's Top Viewed Threat Actor Profiles

If you're logged into Validin, view the full profiles:

  1. Lazarus Group
  2. ClickFix
  3. Kimsuky
  4. Fake Software Downloads
  5. Lumma Stealer
pivots revisited

YEP... STILL GOOD

Pivots Revisited: Still Valid Months Later?

In this blog post, we revisit some of our old blog posts from the last few months to determine how relevant specific pivots and techniques mentioned in the posts are to current investigations of their respective threats. Following the detailed, step-by-step processes for pivoting found in each of the four blogs we analyzed, all resulted in connection to new indicators long after the posts were initially published.  👉 Read the guide now

Get in touch

Contact us

Validin is the first tab I open every morning.
Senior Analyst, Financial Services IT Company